1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
//! # phoxal
//!
//! A production-oriented framework for autonomous robots.
//!
//! Phoxal gives a robot a small, strongly-typed core: a contract bus over
//! [Zenoh](https://zenoh.io), train-selected concrete API contracts,
//! and a
//! participant authoring model where a role marker plus a direct trait
//! implementation is a complete service, driver, or simulator. The framework owns the
//! awkward parts - argument parsing, bus connection, scheduling, query serving,
//! shutdown, and health - so the code you write is the robot's behavior, not its
//! plumbing.
//!
//! Three ideas hold it together:
//!
//! - **A typed contract bus.** Every message is a plain serde body bound to one
//! version-qualified contract name. Handles are endpoint-typed
//! ([`StatePublisher<T>`](bus::StatePublisher),
//! [`StateView<T>`](bus::StateView), [`SampleReceiver<T>`](bus::SampleReceiver),
//! [`Querier<Req, Resp>`](bus::Querier)), so the compiler - not a late check -
//! rejects sending the wrong type on a topic. Publishing is additionally
//! gated by the contract's *temporal* role: the robot time a publisher can
//! express is fixed by what the contract is, so a participant cannot stamp an
//! instant it never reached.
//! - **One train-selected API facade.** Official participants import
//! `phoxal::api`, which names the complete concrete revision selected by the
//! locked framework train. Contract identity is realized on the wire by the
//! revision-qualified key.
//! - **Participants are authored, not wired.** A role attribute declares
//! identity and associated `Config`/`State`/`Api` types; a direct
//! [`Participant`] implementation owns lifecycle
//! behavior, and [`run`] turns the marker into a binary. Use `service` for ordinary robot
//! participants, `driver` for a participant launched once per
//! `robot.components` entry, `simulator` for simulation-only
//! participants, and `brain` for the robot project's one mandatory
//! composition root.
//!
//! ## Author a participant
//!
//! A participant is a unit role marker, optional `Config`/`State`/`Api` types,
//! and one direct trait implementation:
//!
//! ```ignore
//! use phoxal::api;
//! use phoxal::prelude::*;
//!
//! struct Api {
//! state: StateView<api::endpoint::drive::StateEndpoint>, // keep-last drive state
//! target: SetpointPublisher<api::endpoint::drive::TargetEndpoint>, // commanded drive target
//! }
//!
//! #[phoxal::service(id = "avoid-obstacles", api = Api)]
//! struct AvoidObstacles;
//!
//! impl Participant for AvoidObstacles {
//! async fn setup(
//! &self,
//! ctx: &mut SetupContext<Self>,
//! _config: Self::Config,
//! ) -> Result<(Self::State, Self::Api)> {
//! Ok(((), Api {
//! state: ctx.state_view(api::topic::client().drive().state()).await?,
//! target: ctx.setpoint_publisher(api::topic::client().drive().target())?,
//! }))
//! }
//!
//! #[phoxal::step(hz = 50)]
//! fn step(
//! &self,
//! api: &Self::Api,
//! _step: StepContext,
//! _state: &mut Self::State,
//! ) -> Result<()> {
//! api.target.send(api::drive::Target::try_new(0.2, 0.0)?)?;
//! Ok(())
//! }
//! }
//!
//! fn main() -> phoxal::Result<()> { phoxal::run::<AvoidObstacles>() }
//! ```
//!
//! What each piece does:
//!
//! - `use phoxal::api;` brings the versioned API module into scope;
//! `Api` struct fields name train-selected bodies (`api::drive::Target`)
//! directly, with no participant-local version attribute to keep in sync.
//! - The role attribute records identity and sets associated types. Omitted
//! `Config`, `State`, and `Api` default to `()`.
//! - Handles are ordinary fields built in `Participant::setup` from typed topic
//! builders and returned alongside mutable state.
//! - `#[phoxal::step(hz = ...)]` adds a cadence to the trait's step override.
//! - `ctx.query(owner_endpoint, Self::handler)` registers typed query handlers;
//! the endpoint fixes the handler's request and response types at compile time,
//! and the runner supplies trusted requester [`QueryContext`] provenance.
//! - The runner serializes step, query, reset, and shutdown access to `State`.
//! - `fn main() -> phoxal::Result<()> { phoxal::run::<R>() }` is the default
//! blocking entrypoint. For a custom Tokio main, call
//! [`phoxal::tokio::run::<R>().await`](tokio::run).
//!
//! The four authoring kinds share the same metadata path but describe
//! different runtime roles:
//!
//! - [`macro@service`] is the ordinary typed participant surface.
//! - [`macro@driver`] is launched once per `robot.components` entry. Only a
//! driver can call
//! [`SetupContext::component`]
//! to read the bound component instance.
//! - [`macro@simulator`] is a normal participant for simulation-only processes.
//! It carries a distinct kind and marker for simulation clock ownership.
//! - [`macro@brain`] is the robot project's one mandatory composition root:
//! the root Cargo package's binary, staged as `bin/brain`. Its identity is
//! fixed to `brain` and its `Config` is always `()`; it owns mission and
//! intent policy as ordinary Rust code and holds no capability a service
//! does not. It is never declared under `robot.yaml` `services:`.
//!
//! Worked examples live in `phoxal/examples/`.
//!
//! ## Where to look next
//!
//! - The `phoxal-api` crate (`phoxal::api`, …) - the versioned API
//! modules: version-local wire bodies, the [`ApiVersion`](bus::ApiVersion) /
//! endpoint descriptor traits and API-local topic builders, all generated
//! from modular `phoxal_api_tree!` and `phoxal_api_fragment!` declarations.
//! A participant imports it directly with `use phoxal::api as api;`.
//! The runner also links it for framework-owned out-of-band infrastructure
//! contracts such as bus logs.
//! - [`prelude`] - everything a participant author imports with
//! `use phoxal::prelude::*;`: the handle types, [`SetupContext`],
//! [`StepContext`], and [`Result`].
//! - [`bus`] - the typed contract vocabulary normal participants need: the
//! key scheme, MessagePack codec, [`BusMetadata`](bus::BusMetadata) attachment,
//! the four non-interchangeable time types, endpoint-typed handles, and
//! side-branded [`Topic`](bus::Topic) values.
//! - [`model`] - immutable canonical runtime robot facts supplied from the
//! finalized `runtime.json`; bundle assembly and host-side reading live in
//! `phoxal-bundle`, while authored document readers live in
//! `phoxal-manifest` as a build/source dependency only.
//! - [`geometry`] and [`SampleSchedule`] - the small shared arithmetic every
//! official participant would otherwise reimplement.
//! - The **official service set** ships alongside this crate in the workspace
//! `service/` tree (`drive`, `localize`, `map`, `safety`, …): full platform
//! participants authored on exactly this surface, useful as reference reading.
// Generated macro output refers to the framework as `::phoxal::…`; make that path
// resolve to this crate so role/config macros work inside the engine's own tests, the
// same as in downstream service crates. Only the in-crate test build units expand
// macros to `::phoxal::…`, so the alias is needed only under `cfg(test)`; gating
// it there keeps the non-test build free of an unused `extern crate` (no need for
// an `allow(unused_extern_crates)`).
extern crate self as phoxal;
/// Framework-owned transport hand contracts. This module is hidden from the
/// authoring documentation because these endpoints are runtime plumbing, not
/// robot API declarations.
/// Explicit in-process participant testing support.
/// The concrete framework API revision selected by this release train.
/// Typed contract and handle vocabulary for normal participant authoring.
///
/// This is the bus surface a checked participant browses: the contract traits,
/// the codec, the [`BusMetadata`](bus::BusMetadata) attachment, the four
/// non-interchangeable time types, the endpoint-typed handles, and side-branded
/// [`Topic`](bus::Topic) values. Participants build their IO through
/// [`SetupContext`] and the api-local topic builders, so session construction,
/// ownership, raw handles, incoming queries, and server queryables have no
/// place here. Host tooling that owns a session depends on `phoxal-bus`
/// directly; a participant cannot open a second session through this facade.
///
/// [`TimelineAuthority`](phoxal_bus::TimelineAuthority) and
/// [`WorldClockPublisher`](phoxal_bus::WorldClockPublisher) are absent for a
/// stronger reason: they are world-clock authority, which only a
/// `#[phoxal::simulator]` may hold. A simulator reaches them through its
/// role-gated [`SetupContext`] methods and nowhere else, so keeping them off
/// the browsable surface leaves exactly one route to them. See
/// [`TimelineAuthority`](phoxal_bus::TimelineAuthority)'s own docs for how
/// strong that guarantee is.
/// The canonical runtime robot model a [`phoxal_bundle::RuntimeBundle`] yields.
///
/// This mirrors `phoxal-model`'s own facade one-for-one and adds nothing: the
/// names below are the canonical ones, and everything else is reached through
/// the module that owns it ([`model::builder`], [`model::component`],
/// [`model::identity`], [`model::robot`], [`model::simulation`],
/// [`model::structure`]). [`AssetId`] is the logical identity shared by source
/// compilation and the bundle index. Participant asset access is the
/// bundle-owned, digest-checked [`ParticipantAssetResolver`] capability below;
/// source compilation does not cross this runtime boundary.
///
/// [`model::RobotBuilder`] composes a model in memory rather than loading one.
/// A launched participant never needs it - the runner hands it an already-built
/// [`model::Robot`] - but a test or a tool that has no bundle does.
/// The framework result type (`anyhow`-backed). Authoring code uses bare
/// `Result<T>` via the [`prelude`].
pub use Result;
/// Derive a participant config's compile-time JSON Schema from a `Config`
/// struct.
pub use Config;
/// Link a participant state struct to its `Config`/`Api` types as a checked
/// service.
pub use service;
/// Link a participant state struct to its `Config`/`Api` types as a
/// component driver.
pub use driver;
/// Link a participant state struct to its `Config`/`Api` types as a
/// simulation participant.
pub use simulator;
/// Declare the one mandatory root brain, the robot project's composition root.
///
/// Fixed identity `brain` and `Config = ()`; otherwise exactly the checked
/// service surface.
pub use brain;
/// Attach a cadence to `Participant::step`.
pub use step;
/// Run a participant to completion on a framework-owned blocking Tokio runtime.
///
/// This is the default binary entrypoint:
/// `fn main() -> phoxal::Result<()> { phoxal::run::<Participant>() }`.
pub use run;
pub use Participant;
pub use ;
pub use ManagedTaskPolicy;
pub use ParticipantAssets as ParticipantAssetResolver;
pub use AssetId;
pub use ;
/// Async host runner entrypoint for custom Tokio mains
/// (`phoxal::tokio::run::<Participant>().await`).
/// Everything a participant author imports with `use phoxal::prelude::*;`.
/// The macro ABI: the exact set of items the code `phoxal-macros` generates
/// has to be able to name inside a participant's own crate.
///
/// This is not public API. Nothing here carries a stability guarantee, nothing
/// here is documented for authors, and the only code allowed to name any of it
/// is a `#[phoxal::service]` / `driver` / `simulator` / `brain` / `step` /
/// `#[derive(phoxal::Config)]` expansion. Every item is listed explicitly and
/// individually below: a glob re-export here would silently publish the whole
/// participant engine as public API, so the list is the boundary.
///
/// A participant author reaches the same concepts through the crate root, the
/// [`prelude`], and [`bus`]. If something an author needs is only reachable
/// from here, that is a missing facade entry, not a licence to import this
/// module.